CVE-2021-41583
Summary
| CVE | CVE-2021-41583 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-09-24 03:15:00 UTC |
| Updated | 2024-03-12 17:33:00 UTC |
| Description | vpn-user-portal (aka eduVPN or Let's Connect!) before 2.3.14, as packaged for Debian 10, Debian 11, and Fedora, allows remote authenticated users to obtain OS filesystem access, because of the interaction of QR codes with an exec that uses the -r option. This can be leveraged to obtain additional VPN access. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Debian | Debian Linux | 11.0 | All | All | All |
| Application | Eduvpn | Vpn-user-portal | All | All | All | All |
| Operating System | Fedoraproject | Fedora | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Releases · eduvpn/vpn-user-portal · GitHub | Scraper | github.com | Release Notes, Third Party Advisory |
| [eduVPN-deploy] Details Security Issue 2021-08-25 | MISC | list.surfnet.nl | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.